Courseiva

200-201 Security Policies and Procedures Practice Question

An organization is developing an Acceptable Use Policy (AUP). Which of the following topics is typically covered in an AUP?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Prohibition of using company resources for illegal activities

An AUP defines acceptable use of IT resources, including prohibiting unauthorized access, personal use guidelines, and security responsibilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Password complexity requirements

    Why it's wrong here

    Password complexity requirements sit in the password or authentication policy, which defines credential construction rules. An AUP governs acceptable employee use of organisational systems. Password rules are tempting because they are security controls, but they specify credential mechanics rather than permitted user behaviour on assets.

  • ✗

    Incident reporting procedures

    Why it's wrong here

    Incident reporting procedures belong in the incident response plan, which defines detection, escalation and containment steps. An AUP governs acceptable employee use of organisational systems. Reporting procedures are tempting because they involve user duties, but the AUP addresses acceptable use, not the response workflow after an incident.

  • ✗

    Data classification levels

    Why it's wrong here

    Data classification levels belong in a data handling or classification policy, which assigns sensitivity labels and handling rules. An AUP governs acceptable employee use of organisational systems and assets. Classification is tempting because both are security policies, but the AUP addresses user behaviour, not data labelling.

  • ✓

    Prohibition of using company resources for illegal activities

    Why this is correct

    An Acceptable Use Policy defines permitted and forbidden employee behaviour on organisational systems. Prohibiting use of company resources for illegal activities is a core AUP clause, establishing legal boundaries and enabling disciplinary action, directly satisfying the typical AUP content requirement.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.